Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 9th, 2011, 02:51 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,930
Exclamation Trusteer Bypassed !

w32h4x0r has more info etc !

Quote:
I wanted to share here my experience with the security software Trusteer Rapport

*

I tried to download it and break its security, and I have been able to break its layer of security from user mode in less than 10 minutes.

http://www.kernelmode.info/forum/vie...a16290302afe5f

Video here -http://vimeo.com/33341011
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #2  
Old December 9th, 2011, 04:25 PM
shadek's Avatar
shadek shadek is offline
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,817
Default Re: Trusteer Bypassed !

Nice find. Was it x64 platform or 32-bit?
  #3  
Old December 9th, 2011, 06:27 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,110
Default Re: Trusteer Bypassed !

What are the banks going to do now?
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT.
  #4  
Old December 9th, 2011, 07:03 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by The Hammer
What are the banks going to do now?

Sue Trusteer and partner with Webroot?
  #5  
Old December 9th, 2011, 07:24 PM
LoneWolf's Avatar
LoneWolf LoneWolf is offline
Massive Poster
 
Join Date: Jan 2006
Posts: 3,141
Default Re: Trusteer Bypassed !

Thats why a layered defense is the best defense.
Relying on one solution in todays world is to risky, if it's bypassed it's game over.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #6  
Old December 9th, 2011, 07:53 PM
AaLF's Avatar
AaLF AaLF is offline
Frequent Poster
 
Join Date: Feb 2005
Location: Sydney
Posts: 794
Default Re: Trusteer Bypassed !

Trouble is only a handful of people use a layered defense. The masses expect Trusteer to deliver just as they expect an AV to deliver etc. And they dont have the time. SET & FORGET is what's demanded.

If Trusteer was breached then what about the Internet Security Suites. Many boast safe-on-line banking. I'll bet they haven't made as much effort as Trusteer.
  #7  
Old December 9th, 2011, 08:49 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Trusteer Bypassed !

Sometime ago I came with the perfect solution to defeat keyloggers running in user land, under Windows Vista/7.

Keyloggers were completely blind to the browsers.

Obviously, it was just a test. But, I've set the browser with an explicit high integrity level, and I've applied the flags NoReadUp, NoWriteUp and no NoExecuteUp.

I think NoReadUp would suffice, though. I need to verify it.

I ran the browser as administrator, because you can only run High integrity level objects and containers as administrator.

But, by allowing communications to happen only with the bank's IP(s), then what harm can happen? That would mean intruders were already inside the bank's servers, wouldn't it?

Crazy ideas...
  #8  
Old December 9th, 2011, 09:33 PM
AaLF's Avatar
AaLF AaLF is offline
Frequent Poster
 
Join Date: Feb 2005
Location: Sydney
Posts: 794
Default Re: Trusteer Bypassed !

Quote:
Obviously, it was just a test. But, I've set the browser with an explicit high integrity level, and I've applied the flags NoReadUp, NoWriteUp and no NoExecuteUp.

Anything like that in XP?

So does this leave Prevx safeonline as the only free alternative?

Last edited by AaLF : December 9th, 2011 at 09:54 PM.
  #9  
Old December 9th, 2011, 10:07 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by AaLF
Anything like that in XP?

So does this leave Prevx safeonline as the only free alternative?

Microsoft only implemented integrity levels in Windows Vista+. Windows XP users have no luck.

The only alternative would be to run the browser in a secure desktop. avast! paid products offer this functionality.

There's at least one more application (free; I think the code is available as well), that would allow people to do that as well (to run applications in a secure desktop). I don't recall the name. I'll have to look it up.
  #10  
Old December 9th, 2011, 11:33 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Trusteer Bypassed !

Programs running in the secure desktop vs. keyloggers, screen loggers, etc.
  #11  
Old December 10th, 2011, 05:43 AM
vojta vojta is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 464
Default Re: Trusteer Bypassed !

http://www.trusteer.com/support/en/about-rapport

Is Rapport hacker-proof?

Unfortunately, no security solution is. Rapport adds a very important and unique security layer that allows your bank to better protect your sensitive information and promptly react to threats aimed directly at you. With Rapport you are more secure and your bank has better mechanisms to protect your money. However, security is a constant battle and Rapport, as your antivirus solution or any other security product you use, makes it harder for criminals to commit crime.


It's really amusing to see "it's the end of Trusteer!" reactions just because of the typical "see how I bypassed X" video. What security app is immune to this? None.
  #12  
Old December 10th, 2011, 09:15 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Trusteer Bypassed !


That's it! Thanks!
  #13  
Old December 10th, 2011, 01:06 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,930
Default Re: Trusteer Bypassed !

@ vojta

I don't see any "it's the end of Trusteer!" reactions ? only justified concerns !

Quote:
What security app is immune to this? None.

How do you know that ?

Over on KM w32h4x0r has asked for other Apps to test it against, so hopefully we''ll see how they shape up, or not
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #14  
Old December 11th, 2011, 05:10 AM
vojta vojta is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 464
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by CloneRanger
@ vojta

I don't see any "it's the end of Trusteer!" reactions ? only justified concerns !

Like in...

Quote:
Originally Posted by The Hammer
What are the banks going to do now?
Quote:
Originally Posted by m00nbl00d
Sue Trusteer and partner with Webroot?
Quote:
Originally Posted by AaLF
So does this leave Prevx safeonline as the only free alternative?

Now, if you tell me that they are just jocking around, that's another thing.


Quote:
Originally Posted by CloneRanger
How do you know that ?

That no app is immune and everyone can be bypassed one way or another by a hacker operating with admin privileges in front of a computer? I don't know, crazy ideas. For example, Safe Online, that has been quoted here as an alternative to the the now 'flawed' trusteer, is bypassed east, west, north and south by the MRG's simulators and their real world malware tests daily.
  #15  
Old December 11th, 2011, 11:47 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by vojta
Like in...





Now, if you tell me that they are just jocking around, that's another thing.
[...]

I obviously cannot answer for the others, but I fail to see how my comment fits on your description, "it's the end of Trusteer!"?

Now, if you don't know whether or not someone is joking, perhaps you should ask the person directly.
  #16  
Old December 11th, 2011, 03:12 PM
Esse Esse is offline
Regular Poster
 
Join Date: May 2011
Posts: 147
Default Re: Trusteer Bypassed !

Nice explanation of Rapport and its functions, regarding this video by Chris over at MRG.

http://forums.malwareresearchgroup.c....php?f=7&t=634

/Esse
  #17  
Old December 12th, 2011, 06:14 AM
vojta vojta is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 464
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by Esse
Nice explanation of Rapport and its functions, regarding this video by Chris over at MRG.

http://forums.malwareresearchgroup.c....php?f=7&t=634

/Esse

"Yeah, we saw this. The fact of the matter is you can design a POC tool to bypass ANY specific security application."


A very interesting post, including the last paragraph.
  #18  
Old December 12th, 2011, 03:50 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by vojta
That no app is immune and everyone can be bypassed one way or another by a hacker operating with admin privileges in front of a computer? I don't know, crazy ideas. For example, Safe Online, that has been quoted here as an alternative to the the now 'flawed' trusteer, is bypassed east, west, north and south by the MRG's simulators and their real world malware tests daily.

This is not true with the updated version of WSA in 8.0.1.x, and we will be offering a free version similar to SafeOnline in the coming weeks
  #19  
Old December 12th, 2011, 05:01 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,565
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by PrevxHelp
This is not true with the updated version of WSA in 8.0.1.x, and we will be offering a free version similar to SafeOnline in the coming weeks

I suppose it's always good to have one more coming to the fight - in the freeware world.

I don't mean to hijack this thread, so you can answer in Prevx forum or PM, but will it come as a Xmas present?
  #20  
Old December 12th, 2011, 06:22 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,411
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by PrevxHelp
This is not true with the updated version of WSA in 8.0.1.x, and we will be offering a free version similar to SafeOnline in the coming weeks
What's new with the new version of WSA that it won't be bypassed by MRG's tests?
  #21  
Old December 12th, 2011, 06:23 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by Thankful
What's new with the new version of WSA that it won't be bypassed by MRG's tests?

I don't want to derail the thread but we made several improvements about a month ago which closed off any known vulnerabilities from malware or other testing.
  #22  
Old December 12th, 2011, 06:42 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,411
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by PrevxHelp
I don't want to derail the thread but we made several improvements about a month ago which closed off any known vulnerabilities from malware or other testing.
Great.
  #23  
Old December 12th, 2011, 08:16 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,110
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by PrevxHelp
I don't want to derail the thread but we made several improvements about a month ago which closed off any known vulnerabilities from malware or other testing.
Looks like you've been beat again. Or does this not count? http://malwareresearchgroup.com/
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT.
  #24  
Old December 12th, 2011, 08:18 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Trusteer Bypassed !

Quote:
Originally Posted by The Hammer
Looks like you've been beat again. Or does this not count? http://malwareresearchgroup.com/

And the cat/mouse game continues
  #25  
Old December 12th, 2011, 08:40 PM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,309
Default Re: Trusteer Bypassed !

As always is the case between vendor & malware authors/researchers.

Last edited by TonyW : December 12th, 2011 at 08:50 PM.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:12 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums